devops-kung-fu / bomber

Scans Software Bill of Materials (SBOMs) for security vulnerabilities
Mozilla Public License 2.0
480 stars 42 forks source link

VS Code extension #180

Open nhopkins19 opened 8 months ago

nhopkins19 commented 8 months ago

Create a VS Code extension, potentially integrated with Co-Pilot, for Bomber. Maybe we can somehow package Bomber with Syft or CycloneDX, and then working together with AI, have Bomber help facilitate the creation of a SBOM,etc

nhopkins19 commented 8 months ago

I wonder how or if we need to incorporate this latest CVSS update: https://www.first.org/cvss/v4-0/